Tagged “osv”
CVEs tagged osv, newest first.
5712 CVEsRSS
CVE-2024-29033High· 7.5GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
CVE-2024-21503Medium· 5.3Black vulnerable to Regular Expression Denial of Service (ReDoS)
Black vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2024-1753High· 8.6PoCA flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers
A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to the ro…
CVE-2024-21661High· 7.5Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
Denial of Service (DoS) Vulnerability Due to Unsafe Array Modification in Multi-threaded Environment
CVE-2024-28248High· 7.2Intermittent HTTP policy bypass
Intermittent HTTP policy bypass
CVE-2024-21652Medium· 5.4Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
CVE-2024-28865High· 7.5Denial of service via regular expression
Denial of service via regular expression
CVE-2024-29156Medium· 6.5Information leakage in YAQL
Information leakage in YAQL
CVE-2023-41334High· 8.4RCE in TranformGraph().to_dot_graph function
RCE in TranformGraph().to_dot_graph function
CVE-2024-22513LowPoCImproper Privilege Management in djangorestframework-simplejwt
Improper Privilege Management in djangorestframework-simplejwt
CVE-2024-27351Medium· 5.3Regular expression denial-of-service in Django
Regular expression denial-of-service in Django
CVE-2024-28854High· 7.5tls-listener affected by the slow loris vulnerability with default configuration
tls-listener affected by the slow loris vulnerability with default configuration
CVE-2024-28175Critical· 9.0Cross-site scripting on application summary component
Cross-site scripting on application summary component
CVE-2023-50726Medium· 6.4Users with `create` but not `override` privileges can perform local sync
Users with `create` but not `override` privileges can perform local sync
CVE-2024-24770Medium· 5.3vantage6 vulnerable to a username timing attack on recover password/MFA token
vantage6 vulnerable to a username timing attack on recover password/MFA token
CVE-2024-23823Medium· 4.2vantage6's CORS settings overly permissive
vantage6's CORS settings overly permissive
CVE-2024-28423Critical· 9.8Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vuln…
Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted YML file.
CVE-2024-1410Low· 3.7quiche vulnerable to unbounded storage of information related to connection ID retirement
quiche vulnerable to unbounded storage of information related to connection ID retirement
CVE-2024-1765Medium· 5.9quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
CVE-2024-27097Medium· 4.3Potential log injection in reset user endpoint in CKAN
Potential log injection in reset user endpoint in CKAN
CVE-2024-26164High· 8.8Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
CVE-2024-52288Medium· 5.1LibOSDP RMAC revert to the beginning of the session
LibOSDP RMAC revert to the beginning of the session
CVE-2024-2319Medium· 5.4Django MarkdownX Cross-Site Scripting (XSS) vulnerability
Django MarkdownX Cross-Site Scripting (XSS) vulnerability
CVE-2024-52296Medium· 6.5LibOSDP vulnerable to a null pointer deref in osdp_reply_name
LibOSDP vulnerable to a null pointer deref in osdp_reply_name
CVE-2024-28184High· 7.4WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
CVE-2024-1442Medium· 6.0grafana: Improper priviledge managent for users with data source permissions (CVE-2024-1442)
A flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…
CVE-2024-0917Critical· 9.8PaddlePaddle vulnerable to remote code execution
PaddlePaddle vulnerable to remote code execution
CVE-2024-0818Critical· 9.1PaddlePaddle Path Traversal vulnerability
PaddlePaddle Path Traversal vulnerability
CVE-2024-0815High· 8.8PaddlePaddle command injection in paddle.utils.download._wget_download
PaddlePaddle command injection in paddle.utils.download._wget_download
CVE-2024-0817High· 7.8PaddlePaddle command injection vulnerability
PaddlePaddle command injection vulnerability